PT-2002-2462 · Alt N Technologies · Mdaemon
Published
2002-12-31
·
Updated
2017-07-11
·
CVE-2002-1740
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Alt-N Technologies MDaemon versions 5.0.5.0 and earlier
Description
The issue is related to a buffer overflow in WorldClient.cgi, part of WorldClient in Alt-N Technologies MDaemon. This occurs when a local user provides a long folder name via the
NewFolder parameter, allowing the execution of arbitrary code.Recommendations
For versions 5.0.5.0 and earlier, consider restricting access to the WorldClient.cgi until a fix is available, and avoid using long folder names via the
NewFolder parameter to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mdaemon